WatchGuard security advisory (AV26-972)

Canadian Centre for Cyber Security Version 1 original current

Imported from official source

Serial number: AV26-972Date: September 29, 2026 As of September 28, 2026, WatchGuard is affected by vulnerabilities in the following product: WatchGuard AP Prior to 3.4.8 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-101891 — WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access CVE-2026-86102 — WatchGuard AP Command Injection in Internal Management API Allows Command Execution CVE-2026-87969 — WatchGuard AP Authenticated Command Injection in Diagnostic CLI WatchGuard Security Advisories

This version

Version
1 of 1
Recorded
September 29, 2026 14:00
Change
Initial
Content hash
67cd322145b4f24f00dd2aa6c6b56fbc
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.